How Orion will use traditional data sources to identify and label threats

MitreOrion – The Tool:
Orion is a multi-faceted long term project. A part of the Orion Defensive AI system involves analysis and modelling existing attacks and predicting potential attack vectors, especially on Large Language Model-based applications. The most recent data indicates that 50% of Australian SMB businesses do not have an active or enforced cybersecurity policy. Cybersecurity services are incredibly expensive, and the tools to perform cyber attacks have become increasingly affordable.
A key piece of intelligence that the industry uses comes from the MITRE ATT&CK framework for mobile, enterprise, and IoT-based attack tools, techniques, and procedures. The more recent MITRE ATLAS addresses novel attacks currently known by the industry, employing an adversarial AI model. An adversarial AI model is one that either degrades the performance of a model or automates the laborious task of gathering intelligence, analyzing threats, and then mitigating them.
Large-scale, automated attacks based on a combination of traditional machine learning (e.g., identifying weak targets, scanning for potential exploits) can be supplemented by agent networks that perform these attacks, store the results, and continuously develop new attack vectors.
At Synavate Labs, through our Orion network, we are experimenting with and developing techniques to identify and mitigate adversarial AI using industry-known methodologies. We are a small group heading into a big pond, but the need for this service is only going to grow.
Methodology:
MITRE ATT&CK:
The MITRE ATT&CK framework is a comprehensive knowledge base of adversary tactics and techniques based on real-world observations. It is widely used by cybersecurity professionals to understand, detect, and mitigate cyber threats.
MITRE ATLAS:
MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems) focuses on the evolving landscape of adversarial AI threats. It provides insights into how adversaries could exploit AI systems and offers guidance on defense strategies.
Knowledge Graphs:
Part of the strategy that Orion is employing is “Ephemeral Knowledge Graphs” as we have come to call them while our research evolves. These are generated based on threat analysis outputs to model a single or multi-stage attack and are trainable over time for custom models. These ephemeral graphs capture the dynamic nature of threat landscapes, allowing us to adapt quickly to new threats by integrating real-time data and historical context. They are used to represent complex relationships between different entities involved in an attack, such as IP addresses, file hashes, and threat actors. By continuously updating and refining these graphs, we can improve our understanding of adversarial behavior and enhance our defensive measures.
Usage:
Clustering of network traffic for anomaly detection using mathematical techniques such as spectral analysis is where we aim to apply our attention. Although we do not presently have the expertise to execute this at scale effectively, we plan to develop this capability to identify subtle patterns indicative of malicious activities.
Enrichment through LLMs
Orion will enrich the data identified using the capabilities of LLMs (Large Language Models) to retrieve existing information from vector stores and traditional datastores to cohesively link the landscape as it evolves. Our hope, though theoretical at this stage, is that this will enable the development of a wider connectivity landscape. By leveraging LLMs, we aim to provide richer contextual information, improving our threat detection and response capabilities.
Tensor-Based Edge Indexing
To effectively index the MITRE ATT&CK framework and other existing threats using tensor-based edge indexing for analysis, we need to leverage graph representations where edges can hold additional information in the form of tensors. This approach enables us to capture the complexity of relationships between nodes (e.g., tactics, techniques, threat actors) with rich metadata, facilitating more advanced analyses such as pattern recognition, anomaly detection, and threat correlation. Even in the stochastic world of large language models, there are identifiable patterns that can be leveraged for enhanced security insights.

Progress:
The Orion project is 5 months old and at an early stage. According to industry literature, the field is only 3 years old, and the access that Advanced Persistent Threats (Nation States) and others have had to powerful and advanced Large Language Models is relatively new. Regardless of the ongoing progressive development of the industry or if AI falters, the potential for more powerful attacks by various groups is already significantly higher than in the past.
Next Steps:
- Expand Expertise in Spectral Analysis: Build a team or collaborate with experts to enhance our capabilities in clustering and analyzing network traffic using spectral techniques.
- Enhance Tensor-Based Indexing: Develop and refine methods for tensor-based edge indexing to improve the complexity and depth of our threat analysis.
- Integration with Additional Data Sources: Expand data collection to include more diverse sources, such as cloud logs and mobile device logs, to provide a more comprehensive threat landscape.
- Develop Custom Visualization Tools: Create tailored visualization tools to help security analysts understand and explore complex relationships within the knowledge graphs.
- Continuous Improvement of LLM Models: Regularly update and refine our LLM models to maintain and improve the accuracy of our threat detection and enrichment processes.
- Pilot Testing and Feedback: Conduct pilot tests with selected partners to gather feedback and refine our methodologies and tools before broader deployment.
Thank you for reading. If you have expertise in this space and would like to join us on this journey, please get in touch:
Peace and Love World,
Synavate Labs